← Back

CVE-2014-1932

nvd nist
Published: Apr 17, 2014Modified: May 6, 2026

JSON object

Loading...
4.4
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 3.4 / Impact: 6.4
Source: NVD

Description

The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.

Affected (2)

1 product
Pillow
1 product
Python Imaging Library
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.3.0
Up to 1.1.7

Timeline

No history available yet.